diff --git a/.snyk b/.snyk new file mode 100644 index 0000000..b8c3d14 --- /dev/null +++ b/.snyk @@ -0,0 +1,42 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.13.3 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + 'npm:hawk:20160119': + - ecmarkup > highlight.js > gear-lib > less > request > hawk: + patched: '2019-02-25T23:00:10.164Z' + 'npm:http-signature:20150122': + - ecmarkup > highlight.js > gear-lib > less > request > http-signature: + patched: '2019-02-25T23:00:10.164Z' + 'npm:mime:20170907': + - ecmarkup > highlight.js > gear-lib > mime: + patched: '2019-02-25T23:00:10.164Z' + - ecmarkup > highlight.js > gear-lib > less > mime: + patched: '2019-02-25T23:00:10.164Z' + - ecmarkup > highlight.js > gear-lib > less > request > form-data > mime: + patched: '2019-02-25T23:00:10.164Z' + 'npm:minimatch:20160620': + - ecmarkup > highlight.js > gear > liftoff > findup-sync > glob > minimatch: + patched: '2019-02-25T23:00:10.164Z' + - ecmarkup > highlight.js > gear-lib > gear > liftoff > findup-sync > glob > minimatch: + patched: '2019-02-25T23:00:10.164Z' + - ecmarkup > highlight.js > gear-lib > glob > minimatch: + patched: '2019-02-25T23:00:10.164Z' + - ecmarkup > highlight.js > gear-lib > jslint > glob > minimatch: + patched: '2019-02-25T23:00:10.164Z' + - ecmarkup > highlight.js > gear-lib > jshint > cli > glob > minimatch: + patched: '2019-02-25T23:00:10.164Z' + - ecmarkup > highlight.js > gear-lib > jshint > minimatch: + patched: '2019-02-25T23:00:10.164Z' + 'npm:request:20160119': + - ecmarkup > highlight.js > gear-lib > less > request: + patched: '2019-02-25T23:00:10.164Z' + 'npm:tunnel-agent:20170305': + - ecmarkup > highlight.js > gear-lib > less > request > tunnel-agent: + patched: '2019-02-25T23:00:10.164Z' + 'npm:uglify-js:20151024': + - ecmarkup > highlight.js > gear-lib > handlebars > uglify-js: + patched: '2019-02-25T23:00:10.164Z' + - ecmarkup > highlight.js > gear-lib > uglify-js: + patched: '2019-02-25T23:00:10.164Z' diff --git a/package.json b/package.json index 9b1412b..969c02d 100644 --- a/package.json +++ b/package.json @@ -8,9 +8,15 @@ "license": "SEE LICENSE IN https://tc39.github.io/ecma262/#sec-copyright-and-software-license", "homepage": "https://iddan.github.io/proposal-function-expression-decorators/", "dependencies": { - "ecmarkup": "^3.12.0" + "ecmarkup": "^3.12.0", + "snyk": "^1.134.2" }, "devDependencies": { "@alrra/travis-scripts": "^3.0.0" - } + }, + "scripts": { + "snyk-protect": "snyk protect", + "prepublish": "npm run snyk-protect" + }, + "snyk": true }